Suspicious Browser History Dumping via NirSoft Tool via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Discovery → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects execution of the NirSoft BrowsingHistoryView utility, which the REMCOS RAT abuses through its DumpBrowserHistoryUsingNirsoft command to collect victim browsing data. Attackers stage this signed third-party tool to harvest history for reconnaissance and credential context. Its appearance outside sanctioned administrative use is suspicious.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Suspicious Browser History Dumping via NirSoft Tool via process_creation
Pivot detection · T1005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.